Our client, a leading national organization within the financial services and insurance industry, is seeking a Senior Cybersecurity Standards & Policies Specialist. In this strategic assignment, you will play a central role in driving the comprehensive modernization of the enterprise security policy framework. You will help shift the organizational mindset from a traditional compliance-driven model to a practical, security-first methodology. Your work will focus on creating clear, actionable standards that empower both the general workforce and specialized IT and Cyber teams.
...
Advantages
Flexible Hybrid Model: Balanced hybrid work environment requiring only 2 days per week in the office.
Extension Potential: Initial 6-month consulting engagement with strong potential for subsequent renewals.
Geographic Flexibility: Opportunity to work from major office locations across Canada (including Montreal, Laval, Quebec City, Toronto, Calgary, Edmonton, or Vancouver).
Strategic Influence: High-impact mandate reshaping security governance for an industry leader.
Modern Tooling: Exposure to modern GRC platforms and innovative policy delivery channels.
Responsibilities
Oversee the end-to-end lifecycle (authoring, updating, and retiring) of organizational cybersecurity policies, standards, and technical baselines.
Produce dual-layered documentation: concise, plain-language guidance for non-technical staff and rich technical specifications for engineering and operations teams.
Ensure full alignment with financial sector supervisory expectations (e.g., OSFI guidelines, SOX) while eliminating unnecessary administrative friction.
Translate major control frameworks (NIST CSF, NIST SP 800-53, ISO 27001) into practical, actionable technical requirements.
Work collaboratively with security architects, cloud engineers, and risk advisors to ensure controls are operationally feasible.
Establish a systematic governance review cycle and refine the security exception management workflow.
Utilize dynamic content creation tools (Jira, Confluence, SharePoint) to publish accessible governance materials.
Qualifications
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience.
Minimum of 10 years of broad IT or cybersecurity experience, including at least 3 years focused on managing standards and policy frameworks.
Practical experience working with regulatory frameworks within the financial services domain (e.g., OSFI, SOX).
Strong technical grasp across core domains (IAM, Web Application Firewalls, Cloud Security, and server policies).
Exceptional communication skills with a proven track record of tailoring documentation for both executive and technical audiences.
Proficiency with collaborative tools such as Jira, Confluence, and SharePoint.
Relevant industry certifications (e.g., CISSP, CISM, CRISC, CISA, CCSP) are considered a valuable asset.
Our client operates in Canada. The company takes all reasonable steps to limit the number of positions in Quebec that require knowledge of a language other than French, and only requires it when necessary and its existing bilingual employees are unable to perform these duties. Based on an assessment conducted by our client, it has been determined that this position requires candidates to be fluent in English (both spoken and written). In particular, this position will require the employee to interact with centralized internal departments (e.g., Operations / HR / Finance / Legal / Contracts / Sales) that support the organization in Canada and that do not speak French.
Summary
Position Title: Senior Cybersecurity Standards & Policies Consultant
Engagement Type: IT Consulting Contract – 6-month mandate (renewable)
Work Setup: Hybrid (2 days/week on-site)
Location: Flexible options across Canada (Montreal, Laval, Quebec City, Toronto, Calgary, Vancouver, etc.)
Travel Required: None
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
show more
Our client, a leading national organization within the financial services and insurance industry, is seeking a Senior Cybersecurity Standards & Policies Specialist. In this strategic assignment, you will play a central role in driving the comprehensive modernization of the enterprise security policy framework. You will help shift the organizational mindset from a traditional compliance-driven model to a practical, security-first methodology. Your work will focus on creating clear, actionable standards that empower both the general workforce and specialized IT and Cyber teams.
Advantages
Flexible Hybrid Model: Balanced hybrid work environment requiring only 2 days per week in the office.
Extension Potential: Initial 6-month consulting engagement with strong potential for subsequent renewals.
Geographic Flexibility: Opportunity to work from major office locations across Canada (including Montreal, Laval, Quebec City, Toronto, Calgary, Edmonton, or Vancouver).
Strategic Influence: High-impact mandate reshaping security governance for an industry leader.
Modern Tooling: Exposure to modern GRC platforms and innovative policy delivery channels.
...
Responsibilities
Oversee the end-to-end lifecycle (authoring, updating, and retiring) of organizational cybersecurity policies, standards, and technical baselines.
Produce dual-layered documentation: concise, plain-language guidance for non-technical staff and rich technical specifications for engineering and operations teams.
Ensure full alignment with financial sector supervisory expectations (e.g., OSFI guidelines, SOX) while eliminating unnecessary administrative friction.
Translate major control frameworks (NIST CSF, NIST SP 800-53, ISO 27001) into practical, actionable technical requirements.
Work collaboratively with security architects, cloud engineers, and risk advisors to ensure controls are operationally feasible.
Establish a systematic governance review cycle and refine the security exception management workflow.
Utilize dynamic content creation tools (Jira, Confluence, SharePoint) to publish accessible governance materials.
Qualifications
Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent practical experience.
Minimum of 10 years of broad IT or cybersecurity experience, including at least 3 years focused on managing standards and policy frameworks.
Practical experience working with regulatory frameworks within the financial services domain (e.g., OSFI, SOX).
Strong technical grasp across core domains (IAM, Web Application Firewalls, Cloud Security, and server policies).
Exceptional communication skills with a proven track record of tailoring documentation for both executive and technical audiences.
Proficiency with collaborative tools such as Jira, Confluence, and SharePoint.
Relevant industry certifications (e.g., CISSP, CISM, CRISC, CISA, CCSP) are considered a valuable asset.
Our client operates in Canada. The company takes all reasonable steps to limit the number of positions in Quebec that require knowledge of a language other than French, and only requires it when necessary and its existing bilingual employees are unable to perform these duties. Based on an assessment conducted by our client, it has been determined that this position requires candidates to be fluent in English (both spoken and written). In particular, this position will require the employee to interact with centralized internal departments (e.g., Operations / HR / Finance / Legal / Contracts / Sales) that support the organization in Canada and that do not speak French.
Summary
Position Title: Senior Cybersecurity Standards & Policies Consultant
Engagement Type: IT Consulting Contract – 6-month mandate (renewable)
Work Setup: Hybrid (2 days/week on-site)
Location: Flexible options across Canada (Montreal, Laval, Quebec City, Toronto, Calgary, Vancouver, etc.)
Travel Required: None
Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.
Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.
show more